LearnCTEM.com, Best CTEM Learning Platform
CTEM Basics

CTEM Metrics and KPIs: What to Measure and How to Report

A good CTEM metric set separates operational health from outcome. Operational metrics show whether the loop is running well. Outcome metrics show whether risk on critical services is actually going down. A minimum viable set is five to seven metrics; anything more usually creates dashboard fatigue without improving decisions.

Last updated: July 24, 2026

Red bar-chart columns with a rising red trend line representing CTEM metrics over time.

Quick answer

Direct answer

Track a small mix of operational metrics (age, SLA, validated rate, reopened rate) and outcome metrics (critical exposure count and risk reduction on top services). Report to the right audience at the right cadence.

What you will learn

  • The minimum viable CTEM metric set
  • The difference between operational and outcome metrics
  • How each metric can be misused
  • How to report to program, leadership, and board audiences
  • How to set targets that are achievable and honest

Explanation

Fewer is more

Five to seven well-defined metrics beat twenty half-defined ones. Add metrics only when the current set stops answering the question they were meant to answer.

The minimum viable metric set

MetricTypeWhat it showsHow it can be misused
Critical exposure count on top servicesOutcomeCurrent attack surface that matters mostComparing across services with different criticality
Mean exposure age at closureOperationalProgram speed on validated exposuresReporting average without median; a few outliers hide the reality
Validated exposure rateOperationalShare of the register that has been proven vs assumedValidating easy items to inflate the rate
Remediation SLA performanceOperationalHow often SLAs are met, per severity bandLoosening SLAs to hit the target
Reopened exposure rateOperationalQuality of remediation and validationExcluding exceptions from the base to look better
Exception count and ageOperationalHow much accepted risk is on the booksUsing exceptions as a permanent workaround
Risk reduction trend on top servicesOutcomeWhether CTEM is actually reducing business riskReporting one point instead of a trend

Operational vs outcome metrics

Operational metrics tell you whether the loop is running. Outcome metrics tell you whether the loop is producing anything for the business. A healthy dashboard has both. Reporting only operational metrics tells leadership how busy the team is, not whether risk is going down.

TypeQuestion it answersAudience
OperationalIs the CTEM loop running well?Program team, security leadership
OutcomeIs business risk going down?Security leadership, executive leadership, board

Reporting cadence by audience

AudienceCadenceWhat they see
Program teamWeeklyFull operational and outcome set, with drill-down
Security leadershipMonthlyTrend on all metrics, exceptions, top escalations
Executive leadershipQuarterlyOutcome metrics on top services, exceptions, program investments
BoardQuarterly or semi-annualRisk trend on top services, program maturity level, headline exceptions

Setting targets

Targets should be honest and achievable, not aspirational. A good pattern is to baseline in the first cycle, then set improvement targets against the baseline for each subsequent cycle. Common patterns:

  • Reduce critical exposure count on top services by a defined percentage each quarter.
  • Keep validated exposure rate above a defined floor for all critical items.
  • Keep mean exposure age at closure below a defined ceiling, reported as median and average together.
  • Keep reopened exposure rate below a defined ceiling.
  • Keep exception age within a defined limit; force review at expiry.

Metrics that look useful but are not

MetricWhy it looks usefulWhy it fails
Total open findingsBig number, easy to chartWithout asset context, more findings is not more risk
Scanners run per weekShows tool activityActivity is not outcome
Tickets openedShows team is busyOpening more tickets does not reduce risk
Average CVSS scoreFeels quantitativeIgnores exploitability, reachability, and asset importance
Coverage percentage without scope definitionSounds thoroughDenominator drift makes trends meaningless

A short reporting example

A monthly report to security leadership on the checkout service could read: critical exposure count trending down over three cycles, mean closure age within target, validated exposure rate above the floor, one SLA breach explained, two exceptions active with expiry dates, and one recommended investment for the next cycle. That fits on one page.

For more detail on report structure, see CTEM Metrics and Reporting. For roles that consume these metrics, see CTEM Roles and Responsibilities.

How to apply this

  • Adopt the minimum viable metric set for the next cycle
  • Baseline each metric before setting targets
  • Report median alongside average for age metrics
  • Publish a one-page report per audience at the agreed cadence
  • Retire any metric that has not driven a decision in three cycles

Common mistakes

  • Reporting activity metrics to leadership
  • Comparing critical exposure count across services without normalization
  • Loosening SLAs to hit the target
  • Using exceptions as a permanent workaround
  • Adding metrics faster than they can be defined

Key takeaways

  • A minimum viable CTEM metric set is five to seven metrics.
  • Operational and outcome metrics both belong on the dashboard.
  • Audience determines cadence and level of detail.
  • Targets should be baselined before they are set.
  • Any metric that cannot drive a decision should be retired.

Frequently asked questions

Fewer than most teams think. A minimum viable set is five to seven metrics, split between operational health and outcome. Adding more before the basics are stable usually creates dashboard fatigue.

Related pages

Next step

Next: How to start a CTEM program

Turn the metric set into a 30/60/90-day plan.

Author

LearnCTEM Editorial Team

Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.

Reviewed by

Senior CTEM Practitioner Panel

Reviewed for accuracy against public CTEM guidance and real-world program experience.

Sources and further reading

  • Gartner, Implement a Continuous Threat Exposure Management (CTEM) Program (2022). Frames CTEM measurement around outcomes rather than activity.
  • NIST SP 800-55, Performance Measurement Guide for Information Security. Public guidance on operational and outcome-based security metrics.